CVE-2018-3819: Elastic Kibana
Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.
The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security enabled, Kibana versions before 6.1.3 and 5.6.7 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.
Affected products
- Elastic Kibana: before 5.6.7 (fixed in 5.6.7); from 6.0.0, before 6.1.3 (fixed in 6.1.3)
Published 2018-03-30. Last modified 2026-06-17.